SMS should only ever be used as a proof of investment. IE making sure a bit setting up hundreds of thousands of accounts (because they broke your CAPCHA) needs to buy tens of thousands of real phone numbers with service.
It’s a one time thing at account creation and should be immediately deleted afterwards.
Real 2FA should be set up afterwards to actually protect the account. A yubikey or even a simple TOTP app is a lot of protection against account takeover. The only big weakness left at that point is the help desk.
This is only very marginally more effective than SMS. Phishing is way more common and can be automated much more easily than SIM-swapping. With TOTP you close a small window but leave the big door open.
Yubikeys prevent phishing, which is enormously valuable.
There is no help desk that can give away your TOTP secret. That’s the big weakness with SMS, someone buys a phone and asks the clerk to give them your phone number.
Comments
SMS should only ever be used as a proof of investment. IE making sure a bit setting up hundreds of thousands of accounts (because they broke your CAPCHA) needs to buy tens of thousands of real phone numbers with service.
It’s a one time thing at account creation and should be immediately deleted afterwards.
Real 2FA should be set up afterwards to actually protect the account. A yubikey or even a simple TOTP app is a lot of protection against account takeover. The only big weakness left at that point is the help desk.
This is only very marginally more effective than SMS. Phishing is way more common and can be automated much more easily than SIM-swapping. With TOTP you close a small window but leave the big door open.
Yubikeys prevent phishing, which is enormously valuable.
All the arguments in the post against SMS 2FA are also arguments against TOTP
There is no help desk that can give away your TOTP secret. That’s the big weakness with SMS, someone buys a phone and asks the clerk to give them your phone number.
It is a publicized weakness. In practice, phishing is scalable and social engineering isn’t. And humans are shit at detecting phishing attacks.